2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-1633LOW2During the secure boot, bl2 (the second stage of the bootloader) loops over images defined in the table “bl2_mem_params_...
CVE-2024-20925LOW3.1Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). S...
CVE-2024-20923LOW3.1Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). S...
CVE-2024-20911LOW2.6Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a...
CVE-2024-20905LOW2.7Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure S...
CVE-2024-1591LOW3.3Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configure...
CVE-2024-23591LOW2.3ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which...
CVE-2024-0037LOW3.3In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a ...
CVE-2024-25941LOW3.3The jail(2) system call has not limited a visiblity of allocated TTYs (the kern.ttys sysctl). This gives rise to an inf...
CVE-2024-23603LOW3.8 An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software v...
CVE-2024-1454LOW3.4The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment pr...
CVE-2024-23760LOW2.7Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-...
CVE-2024-1439LOW3.3Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbit...
CVE-2024-1433LOW3.7A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the f...
CVE-2024-23319LOW3.5Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message tha...
CVE-2024-0628LOW3.8The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu...
CVE-2024-1048LOW3.3A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will cr...
CVE-2024-20811LOW3.3Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOp...
CVE-2024-20810LOW3.3Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to g...
CVE-2024-23824LOW2.7mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulner...
CVE-2024-21671LOW3.7The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul...
CVE-2024-23743LOW3.3Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: t...
CVE-2024-21336LOW2.5Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-21383LOW3.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-23217LOW3.3A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now